mysite.jp ã¨ãããµã¤ããéç¨ãã¦ãã¦ãæ°ãã« help.mysite.jp ã¿ãããªå¥ãµã¤ãããµããã¡ã¤ã³åã£ã¦ãã¤å¥ã® Web ãµã¼ãã¼ã§ç¨æããã¨ãã¾ãã
ãã®ãµã¤ãã¯ãã«ããã¼ã¸ãã¡ã¤ã³ãªã®ã§é«é¡ãª SSL 証ææ¸ãã¨ãã http ã§è¯ãã¨ãã¦ããâ¦ã¤ããã http://help.mysite.jp
ã¸ã®ãªã¯ã¨ã¹ããä½æ
ãåæã« https://help.mysite.jp
ã«ãªãã¤ã¬ã¯ãããã¦ãã¾ãæãå¥ã®æã¦ã«è¨¼ææ¸ã®ã¨ã©ã¼ãåºã¦ã¢ã¯ã»ã¹ã§ããªãããªãã¦ãã¨ãããã¾ããã
æå㯠help.mysite.jp ã«åé¡ãããã¨æã£ã¦è²ã 調ã¹ã¦ãããã§ãããå®ã¯åé¡ã®ãã£ãã®ã¯ mysite.jp ã®æ¹ãmysite.jp ã¯ãã°ã¤ã³åæã®ãµã¤ãã ã£ãã®ã§ãããªããããè¨å®ãã¦ãã¾ããã
Header set Strict-Transport-Security "max-age=31536000; includeSubDomains"
ãã® Strict-Transport-SecurityãStrict-Transport-Security - HTTP | MDN ã«ããã°
HTTP Strict Transport Security (ãã HSTS ã¨ç¥ããã¾ã) ã¯ãWeb ãµã¤ãããã©ã¦ã¶ã«å¯¾ãã¦ãHTTP ã®ä»£ããã« HTTPS ãç¨ãã¦éä¿¡ãè¡ãããã«ä¼éãããã¨ãã§ããã»ãã¥ãªãã£æ©è½ã§ãã
ã¨ãããã¨ã§ã©ãã https ãã許å¯ãã¦ãªããã¨ãããã¨ã§è¨å®ãã¦ããã®ã§ããããã®ãããã« includeSubDomains
ãä»ãã¦ããããã«ãå¾ããä½ã£ã help.mysite.jp ã«ãåãããªã·ã¼ãé©ç¨ããã¦ãã¾ã£ã¦ãããã¨ã https ãªãã¤ã¬ã¯ãã®åå ã§ããã
ããã§ã®ãã¤ã³ã㯠mysite.jp 㨠help.mysite.jp ãéãWeb ãµã¼ãã¼ã§éç¨ããã¦ãã¦ãã㤠Strict-Transport-Security ã®è¨å®ã¯ mysite.jp ã«ããããã¦ããªãã£ãã¨ããç¹ã§ãã
ä½ãèµ·ãã¦ãããã¨ããã¨ãä¾ãã°ããã¦ã¼ã¶ã¼ã mysite.jp ã«ã¢ã¯ã»ã¹ããã¨ãï¼ï¼ï¼ã«ãµããã¡ã¤ã³ã対象ã«ãã Strict-Transport-Security å ¥ãããããä»ããã¬ã¹ãã³ã¹ãåãã¾ãï¼ï¼ï¼ã
ãã®ã¨ãããã©ã¦ã¶ã¯å é¨ã«æã£ã¦ãã HSTS 対象ã®ãã¡ã¤ã³ãªã¹ãã« mysite.jp ã追å ãã¾ãï¼ï¼ï¼ããã©ã¦ã¶ã¯ãã®ããã« HSTS ã®ããªã·ã¼ãæã£ã¦ãããã¡ã¤ã³ããã£ãã·ã¥ãã¦ã次ã«ã¤ãªãã«ããéã¯å é¨çã«ãªã¯ã¨ã¹ãã https ã«æ¸ãæãã¾ããããã¯ãå é¨ã§å¦çãè¡ããã¨ã§æ¥µåï¼èå¼±ãªï¼ http ã§ã¤ãªãã«ããã®ãé¿ããç®çãããã¾ãã
ä»åã®ã±ã¼ã¹ã§ã¯ includeSubDomains
ã§ãµããã¡ã¤ã³ã対象ã«ãªã£ã¦ãã¾ããã®ã§ã次㫠HSTS ãããç¡ãã§éç¨ããã¦ãã http://help.mysite.jp
ã«ã¢ã¯ã»ã¹ãããã¨ããéããã©ã¦ã¶å
ã®ãã£ãã·ã¥ï¼HSTS ãªã¹ãï¼ãå¹ã㦠https://help.mysite.jp
ã«åãã¦ãã¾ãã®ã§ããï¼ï¼ï¼ã
ã¦ã¼ã¶ã¼ã mysite.jp ã訪ããã«ç´æ¥ help.mysite.jp ã«ã¢ã¯ã»ã¹ããå ´åã¯å½ç¶ HSTS 対象ã®ãã¡ã¤ã³ã¨ãã¦èªèããã¦ãã¾ããããåé¡ãªã http ã§ãµã¤ãã表示ãããã¨ãå¯è½ã§ãã
çµå±ã¯ãã©ã¦ã¶å´ã§ãªããã¦ããèå¼±æ§å¯¾å¿ãªã®ã§ãããæåã«æ¥ç¶ãã«ãã£ã¦ HSTS ããªã·ã¼ãåãåãã¾ã§ã¯ãã¡ã¤ã³ã https ãå¼·å¶ãã¦ããããããã http ã§ã®ããã¨ãã«ãªãå¯è½æ§ãããã¾ããã¾ã HSTS ã«ã¯ max-age
ã¨ãããªãã·ã§ã³ããããã©ã¦ã¶ã HSTS ããªã·ã¼ããã£ãã·ã¥ããæéãè¨å®ãããã¨ãã§ããã®ã§ããããã¾ãé »ç¹ã«ãã£ãã·ã¥ã¢ã¦ããããããªçãæéãè¨å®ãã¦ãã¾ãã¨ãã®åº¦ã« http ã§ã¤ãªãã«ãã£ã¦ãã¾ãå¯è½æ§ãããã¾ãã®ã§ãååé·ãæéãè¨å®ãããã¨ãæ¨å¥¨ããã¦ããããã§ãï¼max-age ã¯ãµã¤ãã«ã¢ã¯ã»ã¹ãããã³ã«æ´æ°ããæéã¯å»¶ã³ã¾ãï¼ã
ä»åã®åé¡ã¯ããã©ã¦ã¶ãæ㤠HSTS ãªã¹ãã«ä¾ãã®ã§ã¦ã¼ã¶ã¼æ¯ã«æåãéããã¾ãå¤é¨ãµã¤ãï¼ãã®å ´å㯠mysite.jp ï¼ã®è¨å®ã«å½±é¿ãåãã¦ããã¨ããç¹ã§ã¡ãã£ã¨åä»ã ã£ãããªã¨æãã¾ãã
æè¨ã¨ãã¦ã¯ã
Strict-Transport-Security ã includeSubDomains ä»ãã§è¨å®ããã¨ãã¯æ¢åã®ãµããã¡ã¤ã³å ¨ã¦ã®ã»ãã¥ãªãã£ããªã·ã¼ã確èªãã¾ããã
ã¨ããã®ã¨ã
æ°ãã«ãµããã¡ã¤ã³åãã¨ãããã®ã«ã¼ããã¡ã¤ã³ã§ includeSubDomains ä»ã Strict-Transport-Security ãè¨å®ãã¦ããªãã確èªãã¾ããã
ã¨ãããã¨ã§ããããã
ã¡ãªã¿ã«ãChrome ãªã©ã§ã¯ preloaded list ã¨ãã¦äºãããã¤ãã®ãã¡ã¤ã³ã HSTS ãªã¹ãã«æã£ã¦ããããã§ããã¾ãã¦ã¼ã¶ã¼ãèªåã§ãã¡ã¤ã³ã HSTS ãªã¹ãã«è¿½å ãããã¨ãã§ãã¾ãããé·ããªã£ã¦ãã¾ã£ãã®ã§ããã¯ãã©ã¦ã¶éã®æåã®éãã¨ä¸ç·ã«ã¾ã次åæ¸ããã¨æãã¾ãã
åè)